South Africa

Country

Cyberattack Disrupts South African Airlines’ Internal Operations

May 3, 2025

South Africa’s state-owned airline said a cyberattack temporarily disrupted its website and several internal operational systems. The attack also affected its mobile application; the IT team was able to contain the incident and “minimize disruption to core flight operations.”

The airline did not respond to requests for comment about whether the incident involved ransomware. CEO John Lamola said they are currently investigating the incident to “determine the root cause” and are looking into the potential leak of sensitive information.

read more

Cyberattack Compromised Customer Data at Mobile provider MTN

April 25, 2025

African mobile giant MTN Group announced that a cybersecurity incident has compromised the personal information of some of its subscribers in certain countries. The telecom giant noted that its network and billing systems weren’t impacted by the attack, though an investigation to determine the exact scope and impact is ongoing.

While the company hasn’t said exactly which countries were affected, MTN Ghana revealed that approximately 5,700 customers may have been impacted, prompting Ghana’s Data Protection Commission to launch an investigation. At the time of writing, no ransomware actors have claimed responsibility for an attack at MTN.

read more

South Africa’s Largest Poultry Producer Profits Fall after Cyberattack

March 16, 2025

Astral Foods confirmed it suffered a cybersecurity incident on March 16, 2025. The attack lead to downtime in the poultry processing division, impacting deliveries to customers and causing a backlog in production. Although the company swiftly implemented disaster recovery protocols, the temporary halt in operations resulted in financial losses.

read more

Systems Offline at National Health Laboratory Service (NHLS) in South Africa

June 26, 2024

The National Health Laboratory Service (NHLS) has confirmed that it experienced an information technology (IT) security breach compromising its systems and infrastructure. A preliminary investigation, suggests that no patient data has been lost or compromised. The organisation’s systems remain inaccessible both internally and externally, including to and from healthcare facilities until the integrity of the environment is secured and repaired.

“It has been established that sections of our system have been deleted, including in our backup server and this will require rebuilding the affected parts. Stakeholders and the public will be informed as soon as more information becomes available. all of its laboratories are currently fully functional and are receiving and processing clinical samples.

Under normal circumstances, the laboratory reports are automatically generated and sent to clinicians or made available on web view, but the incident has disabled that functionality. “However, all urgent results are communicated telephonically to requesting clinicians.”

read more

Sibanye-Stillwater reports Limited Disruptions in Mining and Metals Processing Operations

July 8, 2024

Sibanye-Stillwater suffered an ongoing cyberattack that disrupted its IT systems globally.
The South African miner said it took immediate steps to proactively isolate IT systems and safeguard data as soon as it became aware of the incident.

The cyberattack brought down the company’s servers, causing disruptions to certain areas of its global operations. On Wednesday, officials from its Montana operations told local media that the smelter operations in Columbus, Ohio were impacted after its automated systems all went down.

It is unknown at this time who is behind the attack.

read more

Phishing Attack Hits South African Railways

February 2, 2024

South Africa’s railway agency, PRASA, recently disclosed a significant loss of $1.6 million due to a phishing scam in its annual report. Despite efforts to recover the stolen funds, just over half has been successfully retrieved, leaving the investigation ongoing. While details of the attack remain undisclosed, security experts suspect insider involvement, underscoring the importance of addressing insider threats within organizations.

read more

Reportedly Disruptive Cyberattack at Porsche South Africa’s Headquarters

February 19, 2023

Porsche South Africa’s headquarters in Johannesburg suffered a disruptive ransomware attack over the weekend, taking down several of the company’s systems and at least some backups.

MyBroadband news outlet in SA understands the attackers used a relatively new ransomware strain called Faust to encrypt the company’s files and lock it out of corporate systems. The news outlet contacted Porsche South Africa for further details about the incident, but it declined to comment — neither confirming nor denying the attack.

read more

Unknown Actor Targets South African Power Generator

March 8, 2023

Researchers have uncovered a suspected cyberattack targeting a power generator in southern Africa with a new variant of the SystemBC malware. The attack was carried out by an unknown hacker group in March of this year, according to a report by cybersecurity firm Kaspersky. The hackers used a Cobalt Strike tool and DroxiDat — a new variant of the SystemBC payload — to profile compromised systems and establish remote connections on the electric utility.

No ransomware was delivered to the organization, however.

read more

RansomHouse Gang Claims Attack on Largest Supermarket Chain in Africa

June 10, 2022

Shoprite has been hit by a ransomware attack. On June 10 the company disclosed that they suffered a security incident. RansomHouse, a ransomware gang, has claimed responsibility for the cyberattack, which compromised customer data in Eswatini, Namibia and Zambia. Shoprite said the data breach “included names and ID numbers but no financial information or bank account numbers.”

In messages posted on RansomHouse’s Telegram channel and seen by TechCrunch, the gang, which is said to be targeting companies with weak security, claimed to have obtained 600 gigabytes of data from Shoprite. It said to have collected personal data that was “in plain text/raw photos packed in archived files, completely unprotected.”

read more